Monday, December 9, 2024

[USN-7142-1] WebKitGTK vulnerabilities

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmdXCgIACgkQZWnYVadE
vpOIBQ/+Lszj6RO/muRZkm4+0q+jlrhAxwfjph3ooRJLNlQpVyuaqDNBJQL9xtN9
roXdJD4BMBhHYb9jFGFDQ5scwcE/IzuM4rJVzyqNM384CFuIok6fkd4J6UYbubtV
mX000d4YG6mp7KyUEJIR7brfPh632JbbTeEOYg4QUXSw4Si0Oag1a4mPsUmaoF20
saBUfzV08ncPtn8gflyKy8lMi2vqKapwAIbJFX4I6hbhXyCCgiMIxHVUI9iw8BmS
rCEhiSMeDxUN7CXc7Kt/9DyHiDH3RMEgN+SkYs0VwQc7IExe+xHcTvZVHyw+Pwrf
q9H1JPTlcdeV9GmttBWp5advaQcZnBK5bWazX0GLBg2ZBfCLlcsziR3LGWGnqy3O
Y2UiZGJHKWZY0FKvfmhIDgKhebNmXvDE64nCIIa/MS6hcxuOaKSBfZM+U0jBgbnR
AH6WUlGbNColTy3UaJg7kwbf12V1Y+/HwRsmJplSmrg/chCJWxG7d4a2VTNZR9+u
VEekNAVBD3IABzdf6AFeojhzHoZNZaaJ/RZ4fNWgPYazsVLt1Wo5GveHdb0MOLHA
XBb+44463P1E1t1V2+YIMuteuHQQiN57uJiryBthdRIjmmuAsHvC7SzXpGXvrnZe
08uOeL6tFsxpD0DVypXu+B8oZmazjnfGQV1NSq1CKunMSJ+Zmks=
=C7To
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7142-1
December 09, 2024

webkit2gtk vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in WebKitGTK.

Software Description:
- webkit2gtk: Web content engine library for GTK+

Details:

Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
libjavascriptcoregtk-4.1-0 2.46.4-0ubuntu0.24.10.1
libjavascriptcoregtk-6.0-1 2.46.4-0ubuntu0.24.10.1
libwebkit2gtk-4.1-0 2.46.4-0ubuntu0.24.10.1
libwebkitgtk-6.0-4 2.46.4-0ubuntu0.24.10.1

Ubuntu 24.04 LTS
libjavascriptcoregtk-4.1-0 2.46.4-0ubuntu0.24.04.1
libjavascriptcoregtk-6.0-1 2.46.4-0ubuntu0.24.04.1
libwebkit2gtk-4.1-0 2.46.4-0ubuntu0.24.04.1
libwebkitgtk-6.0-4 2.46.4-0ubuntu0.24.04.1

Ubuntu 22.04 LTS
libjavascriptcoregtk-4.0-18 2.46.4-0ubuntu0.22.04.1
libjavascriptcoregtk-4.1-0 2.46.4-0ubuntu0.22.04.1
libjavascriptcoregtk-6.0-1 2.46.4-0ubuntu0.22.04.1
libwebkit2gtk-4.0-37 2.46.4-0ubuntu0.22.04.1
libwebkit2gtk-4.1-0 2.46.4-0ubuntu0.22.04.1
libwebkitgtk-6.0-4 2.46.4-0ubuntu0.22.04.1

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7142-1
CVE-2024-44308, CVE-2024-44309

Package Information:
https://launchpad.net/ubuntu/+source/webkit2gtk/2.46.4-0ubuntu0.24.10.1
https://launchpad.net/ubuntu/+source/webkit2gtk/2.46.4-0ubuntu0.24.04.1
https://launchpad.net/ubuntu/+source/webkit2gtk/2.46.4-0ubuntu0.22.04.1

No comments:

Post a Comment